The XSS inside your favorite iOS app

A WKWebView without explicit download handling can render a response marked Content-Disposition: attachment instead of downloading or blocking it. When a service hosts user uploads on a trusted origin, an attacker can upload HTML and distribute a direct file URL that becomes active content inside an application's embedded browser.
The default behavior demonstrated in the article is sandboxed HTML and CSS rendering. That is sufficient for trusted-origin UI spoofing and state-changing GET requests through elements such as <img>. JavaScript execution is not universal: the authors observed full XSS only in specific application and response combinations.
Firefox and Firefox Focus for iOS confirmed the broader mechanism. Firefox ignored the attachment disposition, while Focus also rendered binary MIME types; Mozilla tracked the issues as CVE-2025-55030 and CVE-2025-55032 and fixed both. The article also reports affected social in-app browsers, wallet dApp browsers, and PlayStation browsers, but not every listed application has a published independent advisory.
Exploitation requires attacker-controlled file contents on a useful origin and a victim opening the direct URL in an affected embedded browser. Applications can prevent the transition by handling decidePolicyFor navigationResponse and choosing .download or .cancel for attachment or unsupported MIME responses.
Vulnerabilities
6.1
CVE-2025-55030
6.1
CVE-2025-55032
Researchers
Renwa
Vendors
Mozilla
Products
Firefox
Firefox Focus For Ios
Ios
Playstation Browsers
Wkwebview